Identity System of Record: The Three Requirements

Steve Goldberg
Steve Goldberg
Senior Solutions Engineer
August 17, 2026
3 min read
hydden-three-req-hero.png

"System of record" is going to get used a lot in identity over the next year. So it's worth pinning down what the phrase should actually mean for your identity security program.

A record has three properties. It's complete, it's continuous, and it's reconcilable. Miss one and you don't have a record.

Complete

A system of record holds every identity in scope, not the subset that happened to be reachable by your tools. Sixty percent coverage makes a useful report but that report isn't something you can build a governance program on.

And the missing forty percent isn't randomly distributed. It's the systems without a modern API. The homegrown application the payments team wrote in 2011. The mainframe. The critical database. The appliance with an LDAP interface and a CSV export. The Unix hosts with local accounts and SSH keys nobody has inventoried since the last audit. Standing privilege accumulates in exactly these places, because they're the hardest for any tool in the market to reach reliably.

So ask what happens with a system that has no REST API. Then ask how data can be transformed and enriched to meet your specific business requirements. If the answer is a professional services engagement or a manual upload, coverage of that system is a project that will result in expensive and time consuming maintenance.

Continuous

A system of record is true now, not true as of the last collection. A quarterly export is already out of date by the time anyone opens it, because identity changes faster than that.

An account you certified in April can be sitting in a privileged group by May, and the certification will still read as clean. Nothing announces the change. Accuracy that has to be rebuilt by a project every quarter costs the same money every quarter and buys you a few weeks of confidence.

Two questions are worth asking here. How long between a change in the source system and that change appearing in the record? And can you see the change itself, or only the new value? A record that overwrites has no history, and history is what audit and security investigations both run on.

Reconcilable

Identities have to be resolved across systems, so the same human or the same machine appearing in six directories is one entity rather than six rows. Unreconciled accounts break everything downstream, including any automation you try to build on top of them.

Behavioral analytics is the clearest example. Elastic Security Labs argues that most UEBA deployments get their entities wrong from the start, and that once the entity is wrong, everything built on it is contaminated. For example, a shared administrative account gets modeled as though it were one person. Or a service account gets modeled as though it were an interactive person. The same failure is working its way into identity products now, and they'll keep underdelivering until the data underneath them gets fixed.

Any two without the third

The three properties depend on each other. So when somebody tells you they're your system of record, ask which of the three they're missing.

Complete and continuous, without reconcilable, gives you a very fresh pile of lists. Every identity in the estate, updated constantly, and no way to say which human is ultimately responsible for any of it.

Complete and reconcilable, without continuous, gives you an accurate picture of a day that has already passed. Useful for the audit you're in. No use for the alert firing this afternoon.

Continuous and reconcilable, without complete, is the dangerous one. It produces confident, current, well-resolved answers about part of your estate and says nothing about the rest. The systems it can't reach are the systems where standing privilege has been collecting for years.

To see what a system of record will do for your practice, schedule a demo today!

Frequently asked questions

What makes something an identity system of record?

Three properties, and all three at once. It is complete, meaning it holds every identity in scope rather than the subset your tools could reach. It is continuous, meaning it is true now rather than true as of the last collection. And it is reconcilable, meaning the same human or machine appearing in six directories resolves to one entity. Miss any one of them and what you have is a report.

What does complete coverage actually mean?

Every identity in scope, including the systems that are hard to reach. The missing portion is never randomly distributed: it is the homegrown application written in 2011, the mainframe, the critical database, the appliance with an LDAP interface and a CSV export, and the Unix hosts with local accounts and SSH keys nobody has inventoried since the last audit. Standing privilege accumulates in exactly those places, because they are the hardest for any tool to collect from reliably.

Why isn't a quarterly export good enough?

Because identity changes faster than a quarter. An account you certified in April can be sitting in a privileged group by May, and the certification will still read as clean, because nothing announces the change. Accuracy that has to be rebuilt by a project every quarter costs the same money every quarter and buys a few weeks of confidence each time.

What questions should I ask a vendor about how current their data is?

Two. How long between a change in the source system and that change appearing in the record? And can you see the change itself, or only the new value? A record that overwrites has no history, and history is what audit and security investigations both run on.

Why does reconciliation matter for identity analytics?

Because unreconciled accounts contaminate everything built on top of them. Elastic Security Labs argues that most UEBA deployments get their entities wrong from the start, and once the entity is wrong the analytics are too: a shared administrative account gets modeled as though it were one person, or a service account gets modeled as though it were interactive. The same failure is working its way into identity products, and they will keep underdelivering until the data underneath them is fixed.

Which of the three requirements is most dangerous to be missing?

Completeness. Continuous and reconcilable without complete produces confident, current, well-resolved answers about part of your estate and says nothing at all about the rest. The systems it cannot reach are the systems where standing privilege has been collecting for years, so the gap is not just missing data, it is missing the riskiest data.

Share
Steve Goldberg

Steve Goldberg

Senior Solutions Engineer

Senior Solutions Engineer at Hydden. Focused on connecting enterprise security teams with the identity visibility they need.

Stay Ahead of Identity Security Threats

Get the latest insights on identity governance, zero trust, and cybersecurity delivered to your inbox.

© 2026 Hydden Inc. All rights reserved.Privacy PolicyTerms of Service